All MIBs › ZHNFIREWALL
Organization: Zhone Technologies, Inc.
Last Updated: 2012-04-18
Category: Network Security and Firewalls
Description: Manages Zhone Technologies CPE firewall rules, NAT configuration, and packet filtering policy settings.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is ZHNFIREWALL?
ZHNFIREWALL is a Zhone Technologies enterprise MIB that defines LAN management-access filtering and port-forwarding objects for Zhone customer-premises equipment (CPE), mapping directly onto the TR-069 X_ZHONE_MgmtAccessCfg and X_ZHONE_PortForwardingCfg data models. The firewallMgmtAccessTable lets an operator block or allow specific management protocols -- HTTP, HTTPS, ping, SNMP, SNMP trap, SSH, and Telnet -- per LAN interface via firewallMgmtAction, hardening the device's own management plane against external attacks. The firewallPortForwardingTable configures NAT/port-forwarding rules, each specifying a firewallPortType (port range, port remap, or DMZ), a firewallPortProtocol (TCP/UDP/ICMP), a public port range, a private port, and the private IP address traffic is forwarded to, with lifecycle managed through a Zhone-specific RowStatus. As a configuration MIB, monitoring it is mainly about auditing which management services are exposed and which forwarding/DMZ rules are active, since these rules only take effect once the CPE's global firewall object is enabled. It depends on the ZHNLANDEVICE MIB for its lanDeviceIndex/lanEthernetIndex table indexes and the Zhone/Zhone-TC enterprise trees for common types, and it is deployed on Zhone CPE gateways, and administrators can download the ZHNFIREWALL MIB to audit or automate these firewall rules.
IPNetwork Monitor allows you to monitor SNMP objects defined in ZHNFIREWALL. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Zhone Technologies CPE gateways
Monitoring Examples
An operator walks firewallMgmtAccessTable to confirm telnet and http management access are set to deny(2) rather than allow(1), and reviews firewallPortForwardingTable for any DMZ(3) rule; a DMZ rule with a stale firewallPortPrivateIPAddress pointing at a decommissioned host would indicate a forgotten forwarding rule exposing an internal device to all inbound ports.
What Can Be Monitored
- management-access service block/allow state (HTTP, SSH, Telnet, etc.)
- port-forwarding rule type (range/remap/DMZ)
- forwarded protocol and port ranges
- private IP address of forwarding targets
- port-forwarding rule row status
Imported Objects
From SNMPv2-CONF
| MODULE-COMPLIANCE | |
| OBJECT-GROUP |
From SNMPv2-SMI
| Gauge32 | |
| Integer32 | |
| IpAddress | |
| MODULE-IDENTITY | |
| OBJECT-TYPE | |
| Unsigned32 | |
| enterprises |
From SNMPv2-TC
| MacAddress | |
| RowStatus | |
| TEXTUAL-CONVENTION | |
| TruthValue |
From Zhone
| zhoneWtn | OBJECT-IDENTITY |
From Zhone-TC
| ZhoneRowStatus |
OIDs
RFC description
Zhonghua Network firewall management MIB; manages firewall rules, connections, and security policies for ZHN security appliances.
Start monitoring Zhone Technologies CPE gateways (management-access-filter/port-forwarding config status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.